Skip to content

// CVE Tracker

152 active CVEs โ€” page 7 of 7, sorted unpatched-first by CVSS

85

CRITICAL

66

HIGH

152

TOTAL ACTIVE

146

PATCHED

CVSS Scale: 9.0โ€“10.0 CRITICAL ยท 7.0โ€“8.9 HIGH ยท 4.0โ€“6.9 MEDIUM ยท 0.1โ€“3.9 LOW
6.5
CVSS

CVE-2026-20262

Cisco Catalyst SD-WAN Manager โ€” Arbitrary File Overwrite via Malicious Upload Enables Root Privilege Escalation

HIGH โœ“ Patch Available

A file path validation flaw in the web-based management interface of Cisco Catalyst SD-WAN Manager (formerly vManage) allows an authenticated attacker to upload a file to an arbitrary location on the underlying operating system, bypassing the intended upload directory boundary. An attacker with network-operator role privileges โ€” a standard operational credential โ€” can overwrite OS files referenced during service startup or scheduled tasks and execute commands as root. CISA added CVE-2026-20262 to the Known Exploited Vulnerabilities catalogue on 16 June 2026, confirming active in-the-wild exploitation.

Cisco Catalyst SD-WAN Manager (vManage) 20.3 and earlier Cisco Catalyst SD-WAN Manager (vManage) 20.6 through 20.6.4 Cisco Catalyst SD-WAN Manager (vManage) 20.9 through 20.9.3 +1 more
6.5
CVSS

CVE-2026-32201

Microsoft SharePoint Server โ€” Spoofing / Information Disclosure (Actively Exploited Zero-Day)

MEDIUM โœ“ Patch Available

A spoofing vulnerability in Microsoft SharePoint Server allows an authenticated attacker to view sensitive information beyond their authorised scope and make unauthorised modifications to disclosed content, bypassing SharePoint's information barrier and permission controls. The vulnerability was under active exploitation before a patch was available; CISA added it to the Known Exploited Vulnerabilities catalogue on 14 April 2026, the day before Microsoft released the patch in April 2026 Patch Tuesday. The one-day gap between KEV addition and patch release required organisations to make explicit risk acceptance or compensating control decisions.

Microsoft SharePoint Server 2019 Microsoft SharePoint Server Subscription Edition Microsoft SharePoint Foundation 2013 SP1

Note: CVE data is curated manually from NVD, vendor advisories, and security research. CVSS scores reflect NVD base scores at time of entry. Always verify with official vendor advisories before actioning.